Skip to content

Update All v5 dependencies (v5) - #2886

Open
renovate[bot] wants to merge 26 commits into
v5from
renovate/v5-all-v5
Open

Update All v5 dependencies (v5)#2886
renovate[bot] wants to merge 26 commits into
v5from
renovate/v5-all-v5

Conversation

@renovate

@renovate renovate Bot commented Jul 17, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change Pending Age Confidence
JamesIves/github-pages-deploy-action action minor v4.7.3v4.8.0 age confidence
actions/cache action major v4v6.1.0 age confidence
actions/checkout action major v5v7.0.0 age confidence
actions/download-artifact action major v5v8.0.1 age confidence
actions/github-script action major v8v9.0.0 age confidence
actions/setup-java action minor v5v5.4.0 v5.6.0 (+1) age confidence
actions/setup-python action minor v6v6.3.0 age confidence
actions/stale action minor v10v10.3.0 v10.4.0 age confidence
actions/upload-artifact action major v4v7.0.1 age confidence
ad-m/github-push-action action pinDigest 881a632
github/codeql-action action major v3v4.36.3 v4.37.1 (+1) age confidence
gradle (source) major 8.139.6.1 age confidence
gradle/actions action major v4v6.2.0 age confidence
ncipollo/release-action action minor v1v1.21.0 age confidence
python uses-with minor 3.133.14 age confidence
reactivecircus/android-emulator-runner action minor v2v2.37.0 v2.38.0 age confidence
thollander/actions-comment-pull-request action patch v3v3.0.1 age confidence
ts-graphviz/setup-graphviz action patch v2v2.0.2 age confidence
androidx.test.uiautomator:uiautomator (source) dependencies minor 2.3.02.4.0 age confidence
app.cash.turbine:turbine dependencies patch 1.2.01.2.1 age confidence
androidx.test:rules dependencies minor 1.6.11.7.0 age confidence
androidx.test.ext:junit-ktx dependencies minor 1.2.11.3.0 age confidence
org.robolectric:robolectric (source) dependencies minor 4.14.14.16.1 age confidence
org.mockito:mockito-android dependencies minor 5.17.05.23.0 age confidence
org.mockito:mockito-junit-jupiter dependencies minor 5.17.05.23.0 age confidence
org.mockito.kotlin:mockito-kotlin dependencies major 5.4.06.3.0 age confidence
com.android.tools.lint:lint-tests (source) dependencies major 31.8.032.2.1 32.3.0 age confidence
com.android.tools.lint:lint-api (source) dependencies major 31.8.032.2.1 32.3.0 age confidence
com.android.tools.lint:lint (source) dependencies major 31.8.032.2.1 32.3.0 age confidence
org.junit.vintage:junit-vintage-engine (source) dependencies major 5.12.26.1.1 6.1.2 age confidence
org.junit.jupiter:junit-jupiter-params (source) dependencies major 5.12.26.1.1 6.1.2 age confidence
org.junit.jupiter:junit-jupiter-engine (source) dependencies major 5.12.26.1.1 6.1.2 age confidence
org.junit.jupiter:junit-jupiter-api (source) dependencies major 5.12.26.1.1 6.1.2 age confidence
org.json:json dependencies major 2025010720250517 age confidence
androidx.test.espresso:espresso-intents dependencies minor 3.6.13.7.0 age confidence
androidx.test.espresso:espresso-core dependencies minor 3.6.13.7.0 age confidence
androidx.test.espresso:espresso-contrib dependencies minor 3.6.13.7.0 age confidence
com.squareup.retrofit2:converter-moshi dependencies major 2.11.03.0.0 age confidence
com.squareup.retrofit2:retrofit dependencies major 2.11.03.0.0 age confidence
com.squareup.okhttp3:logging-interceptor (source) dependencies major 4.12.05.4.0 age confidence
com.google.android.gms:play-services-wallet dependencies major 19.4.020.0.0 age confidence
com.squareup.okhttp3:mockwebserver (source) dependencies major 4.12.05.4.0 age confidence
com.squareup.okhttp3:okhttp (source) dependencies major 4.12.05.4.0 age confidence
app.cash.paykit:core dependencies minor 2.5.02.6.0 age confidence
androidx.lifecycle:lifecycle-viewmodel-compose (source) dependencies minor 2.8.72.11.0 age confidence
androidx.hilt:hilt-navigation-compose (source) dependencies minor 1.2.01.4.0 age confidence
androidx.compose:compose-bom dependencies major 2025.03.002026.06.01 age confidence
androidx.activity:activity-compose (source) dependencies minor 1.10.11.13.0 age confidence
com.google.android.material:material dependencies minor 1.12.01.14.0 age confidence
androidx.lifecycle:lifecycle-viewmodel-ktx (source) dependencies minor 2.8.72.11.0 age confidence
androidx.lifecycle:lifecycle-runtime-ktx (source) dependencies minor 2.8.72.11.0 age confidence
androidx.fragment:fragment-ktx (source) dependencies patch 1.8.61.8.9 age confidence
org.jetbrains.kotlinx:kotlinx-coroutines-test dependencies minor 1.9.01.11.0 age confidence
org.jetbrains.kotlinx:kotlinx-coroutines-android dependencies minor 1.9.01.11.0 age confidence
org.jetbrains.kotlinx:kotlinx-coroutines-core dependencies minor 1.9.01.11.0 age confidence
org.jetbrains.kotlinx:kotlinx-coroutines-play-services dependencies minor 1.9.01.11.0 age confidence
androidx.browser:browser (source) dependencies minor 1.8.01.10.0 age confidence
androidx.autofill:autofill (source) dependencies patch 1.3.0-rc011.3.0 age confidence
androidx.appcompat:appcompat (source) dependencies patch 1.7.01.7.1 age confidence
androidx.annotation:annotation (source) dependencies minor 1.9.11.10.0 age confidence
androidx.activity:activity (source) dependencies minor 1.10.11.13.0 age confidence
org.jetbrains.kotlinx.binary-compatibility-validator plugin minor 0.16.30.18.1 age confidence
org.sonarqube plugin major 5.1.0.48827.3.1.8318 age confidence
com.pinterest.ktlint:ktlint-cli dependencies minor 1.5.01.8.0 age confidence
org.jetbrains.kotlinx.kover plugin patch 0.9.30.9.8 age confidence
org.gradle.toolchains.foojay-resolver-convention plugin major 0.8.01.0.0 age confidence
com.google.dagger.hilt.android plugin minor 2.552.60 2.60.1 age confidence
com.google.dagger:hilt-android-compiler dependencies minor 2.552.60 2.60.1 age confidence
com.google.dagger:hilt-android-testing dependencies minor 2.552.60 2.60.1 age confidence
com.google.dagger:hilt-compiler dependencies minor 2.552.60 2.60.1 age confidence
com.google.dagger:hilt-android dependencies minor 2.552.60 2.60.1 age confidence
org.jetbrains.dokka plugin major 1.9.202.2.0 age confidence
com.google.devtools.ksp (source) plugin major 1.9.25-1.0.202.3.9 2.3.10 age confidence
org.jetbrains.kotlin.android (source) plugin major 1.9.252.4.0 2.4.10 age confidence
org.jetbrains.kotlin:kotlin-parcelize-runtime (source) dependencies major 1.9.252.4.0 2.4.10 age confidence
com.android.library (source) plugin major 8.8.19.2.1 9.3.0 age confidence
com.android.application (source) plugin major 8.8.19.2.1 9.3.0 age confidence

Release Notes

JamesIves/github-pages-deploy-action (JamesIves/github-pages-deploy-action)

v4.8.0

Compare Source

What's Changed

Build 🔧

Full Changelog: JamesIves/github-pages-deploy-action@v4...v4.8.0

v4.7.6

Compare Source

What's Changed

Build 🔧
  • build(deps): bump typescript-eslint from 8.48.1 to 8.49.0 in the typescript group by @​dependabot[bot] in #​1930

Full Changelog: JamesIves/github-pages-deploy-action@v4...v4.7.6

v4.7.5

Compare Source

What's Changed

Bug Fixes 🐛
Build 🔧

Full Changelog: JamesIves/github-pages-deploy-action@v4...v4.7.5

v4.7.4

Compare Source

What's Changed

Bug Fixes 🐛
Build 🔧
Other Changes
  • Add comprehensive GitHub Copilot instructions for development workflow by @​Copilot in #​1894

Full Changelog: JamesIves/github-pages-deploy-action@v4...v4.7.4

actions/cache (actions/cache)

v6.1.0

Compare Source

What's Changed

Full Changelog: actions/cache@v6...v6.1.0

v6.0.0

Compare Source

What's Changed

Full Changelog: actions/cache@v5...v6.0.0

v5.1.0

Compare Source

What's Changed

Full Changelog: actions/cache@v5...v5.1.0

v5.0.5

Compare Source

What's Changed

Full Changelog: actions/cache@v5...v5.0.5

v5.0.4

Compare Source

What's Changed
New Contributors

Full Changelog: actions/cache@v5...v5.0.4

v5.0.3

Compare Source

What's Changed

Full Changelog: actions/cache@v5...v5.0.3

v5.0.2: v.5.0.2

Compare Source

v5.0.2
What's Changed

When creating cache entries, 429s returned from the cache service will not be retried.

v5.0.1

Compare Source

[!IMPORTANT]
actions/cache@v5 runs on the Node.js 24 runtime and requires a minimum Actions Runner version of 2.327.1.

If you are using self-hosted runners, ensure they are updated before upgrading.


v5.0.1
What's Changed
v5.0.0
What's Changed

Full Changelog: actions/cache@v5...v5.0.1

v5.0.0

Compare Source

[!IMPORTANT]
actions/cache@v5 runs on the Node.js 24 runtime and requires a minimum Actions Runner version of 2.327.1.

If you are using self-hosted runners, ensure they are updated before upgrading.


What's Changed

Full Changelog: actions/cache@v4.3.0...v5.0.0

v4.3.0

Compare Source

What's Changed
New Contributors

Full Changelog: actions/cache@v4...v4.3.0

v4.2.4

Compare Source

What's Changed
New Contributors

Full Changelog: actions/cache@v4...v4.2.4

v4.2.3

Compare Source

What's Changed

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • On day 1 of the month, every 3 months (* * 1 */3 *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Never, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team as a code owner July 17, 2026 11:33
@renovate renovate Bot added the Dependencies [PRs only] Indicates a dependency update label Jul 17, 2026
@renovate

renovate Bot commented Jul 17, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: gradle/libs.versions.toml
Command failed: ./gradlew -Dorg.gradle.jvmargs=-Xms512m -Xmx512m --console=plain --dependency-verification lenient -q --write-verification-metadata sha256 dependencies
WARNING: A restricted method in java.lang.System has been called
WARNING: java.lang.System::load has been called by net.rubygrapefruit.platform.internal.NativeLibraryLoader in an unnamed module (file:/home/ubuntu/.gradle/wrapper/dists/gradle-9.6.1-bin/4ticwg1pgcbps2hj28r8so764/gradle-9.6.1/lib/native-platform-0.22-milestone-29.jar)
WARNING: Use --enable-native-access=ALL-UNNAMED to avoid a warning for callers in this module
WARNING: Restricted methods will be blocked in a future release unless native access is enabled


FAILURE: Build completed with 2 failures.

1: Task failed with an exception.
-----------
* Where:
Build file '/tmp/renovate/repos/github/Adyen/adyen-android/3ds2/build.gradle' line: 9

* What went wrong:
An exception occurred applying plugin request [id: 'kotlin-android']
> Failed to apply plugin 'kotlin-android'.
   > ⛔ Failed to apply plugin 'org.jetbrains.kotlin.android'
     The 'org.jetbrains.kotlin.android' plugin is no longer required for Kotlin support since AGP 9.0.
     Solution: Remove the 'org.jetbrains.kotlin.android' plugin from this project's build file: 3ds2/build.gradle.
     See https://kotl.in/gradle/agp-built-in-kotlin for more details.
      > java.lang.Throwable (no error message)

* Try:
> Run with --stacktrace option to get the stack trace.
> Run with --info or --debug option to get more log output.
> Run with --scan to get full insights from a Build Scan (powered by Develocity).
> Get more help at https://help.gradle.org.
==============================================================================

2: Task failed with an exception.
-----------
* Where:
Build file '/tmp/renovate/repos/github/Adyen/adyen-android/3ds2/build.gradle' line: 9

* What went wrong:
An exception occurred applying plugin request [id: 'kotlin-android']
> Failed to apply plugin 'kotlin-android'.
   > ⛔ Failed to apply plugin 'org.jetbrains.kotlin.android'
     The 'org.jetbrains.kotlin.android' plugin is no longer required for Kotlin support since AGP 9.0.
     Solution: Remove the 'org.jetbrains.kotlin.android' plugin from this project's build file: 3ds2/build.gradle.
     See https://kotl.in/gradle/agp-built-in-kotlin for more details.
      > java.lang.Throwable (no error message)

* Try:
> Run with --stacktrace option to get the stack trace.
> Run with --info or --debug option to get more log output.
> Run with --scan to get full insights from a Build Scan (powered by Develocity).
> Get more help at https://help.gradle.org.
==============================================================================

BUILD FAILED in 1m 11s

@renovate

renovate Bot commented Jul 17, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@jreij
jreij force-pushed the renovate/v5-all-v5 branch 3 times, most recently from b250643 to 90b10d4 Compare July 17, 2026 20:25
@jreij
jreij force-pushed the renovate/v5-all-v5 branch from d5e44ab to f2ab566 Compare August 11, 2026 17:29
Comment thread .github/workflows/publish_docs.yml
@jreij
jreij force-pushed the renovate/v5-all-v5 branch 6 times, most recently from c944849 to 452bdf8 Compare August 12, 2026 08:46
@github-actions

Copy link
Copy Markdown
Contributor

The following dependencies have been modified in this PR:

--- 
+++ 
@@ -1,105 +1,115 @@
-androidx.activity:activity-compose:1.10.1
-androidx.activity:activity-ktx:1.10.1
+androidx.activity:activity-compose:1.11.0
+androidx.activity:activity-ktx:1.11.0
 androidx.activity:activity:1.0.0
-androidx.activity:activity:1.10.1
+androidx.activity:activity:1.11.0
 androidx.annotation:annotation-experimental:1.4.0
 androidx.annotation:annotation-experimental:1.4.1
-androidx.annotation:annotation-jvm:1.9.1
-androidx.annotation:annotation:1.9.1
-androidx.appcompat:appcompat-resources:1.7.0
+androidx.annotation:annotation-jvm:1.10.0
+androidx.annotation:annotation:1.10.0
 androidx.appcompat:appcompat-resources:1.7.1
-androidx.appcompat:appcompat:1.7.0
 androidx.appcompat:appcompat:1.7.1
 androidx.arch.core:core-common:2.1.0
 androidx.arch.core:core-common:2.2.0
 androidx.arch.core:core-runtime:2.0.0
 androidx.arch.core:core-runtime:2.2.0
-androidx.autofill:autofill:1.3.0-rc01
-androidx.browser:browser:1.8.0
+androidx.autofill:autofill:1.3.0
+androidx.browser:browser:1.9.0
 androidx.cardview:cardview:1.0.0
 androidx.collection:collection-jvm:1.4.2
-androidx.collection:collection-jvm:1.4.4
+androidx.collection:collection-jvm:1.5.0
 androidx.collection:collection-ktx:1.1.0
 androidx.collection:collection-ktx:1.4.2
-androidx.collection:collection-ktx:1.4.4
+androidx.collection:collection-ktx:1.5.0
 androidx.collection:collection:1.1.0
 androidx.collection:collection:1.4.2
-androidx.collection:collection:1.4.4
-androidx.compose.runtime:runtime-android:1.7.8
-androidx.compose.runtime:runtime-saveable-android:1.7.8
-androidx.compose.runtime:runtime-saveable:1.7.8
-androidx.compose.runtime:runtime:1.7.8
-androidx.compose.ui:ui-android:1.7.8
-androidx.compose.ui:ui-geometry-android:1.7.8
-androidx.compose.ui:ui-geometry:1.7.8
-androidx.compose.ui:ui-graphics-android:1.7.8
-androidx.compose.ui:ui-graphics:1.7.8
-androidx.compose.ui:ui-text-android:1.7.8
-androidx.compose.ui:ui-text:1.7.8
-androidx.compose.ui:ui-unit-android:1.7.8
-androidx.compose.ui:ui-unit:1.7.8
-androidx.compose.ui:ui-util-android:1.7.8
-androidx.compose.ui:ui-util:1.7.8
-androidx.compose.ui:ui:1.7.8
-androidx.compose:compose-bom:2025.03.00
+androidx.collection:collection:1.5.0
+androidx.compose.runtime:runtime-android:1.9.5
+androidx.compose.runtime:runtime-annotation-android:1.9.5
+androidx.compose.runtime:runtime-annotation:1.9.5
+androidx.compose.runtime:runtime-saveable-android:1.9.5
+androidx.compose.runtime:runtime-saveable:1.9.5
+androidx.compose.runtime:runtime:1.9.5
+androidx.compose.ui:ui-android:1.9.5
+androidx.compose.ui:ui-geometry-android:1.9.5
+androidx.compose.ui:ui-geometry:1.9.5
+androidx.compose.ui:ui-graphics-android:1.9.5
+androidx.compose.ui:ui-graphics:1.9.5
+androidx.compose.ui:ui-text-android:1.9.5
+androidx.compose.ui:ui-text:1.9.5
+androidx.compose.ui:ui-unit-android:1.9.5
+androidx.compose.ui:ui-unit:1.9.5
+androidx.compose.ui:ui-util-android:1.9.5
+androidx.compose.ui:ui-util:1.9.5
+androidx.compose.ui:ui:1.9.5
+androidx.compose:compose-bom:2025.11.01
 androidx.concurrent:concurrent-futures:1.1.0
 androidx.constraintlayout:constraintlayout-core:1.1.1
 androidx.constraintlayout:constraintlayout:2.2.1
 androidx.coordinatorlayout:coordinatorlayout:1.1.0
-androidx.core:core-ktx:1.13.0
+androidx.core:core-ktx:1.13.1
+androidx.core:core-ktx:1.15.0
 androidx.core:core-viewtree:1.0.0
-androidx.core:core:1.13.0
+androidx.core:core:1.13.1
+androidx.core:core:1.15.0
 androidx.core:core:1.2.0
 androidx.cursoradapter:cursoradapter:1.0.0
 androidx.customview:customview-poolingcontainer:1.0.0
 androidx.customview:customview:1.0.0
 androidx.customview:customview:1.1.0
-androidx.databinding:viewbinding:8.8.1
-androidx.documentfile:documentfile:1.0.0
+androidx.databinding:viewbinding:9.2.1
 androidx.drawerlayout:drawerlayout:1.1.1
-androidx.dynamicanimation:dynamicanimation:1.0.0
+androidx.dynamicanimation:dynamicanimation:1.1.0
 androidx.emoji2:emoji2-views-helper:1.3.0
+androidx.emoji2:emoji2-views-helper:1.4.0
 androidx.emoji2:emoji2:1.3.0
-androidx.fragment:fragment-ktx:1.8.6
+androidx.emoji2:emoji2:1.4.0
+androidx.fragment:fragment-ktx:1.8.9
 androidx.fragment:fragment:1.1.0
-androidx.fragment:fragment:1.8.6
+androidx.fragment:fragment:1.8.9
 androidx.graphics:graphics-path:1.0.1
+androidx.graphics:graphics-shapes-android:1.0.1
+androidx.graphics:graphics-shapes:1.0.1
 androidx.interpolator:interpolator:1.0.0
-androidx.legacy:legacy-support-core-utils:1.0.0
-androidx.lifecycle:lifecycle-common-jvm:2.8.7
+androidx.lifecycle:lifecycle-common-jvm:2.9.4
 androidx.lifecycle:lifecycle-common:2.1.0
-androidx.lifecycle:lifecycle-common:2.8.7
-androidx.lifecycle:lifecycle-livedata-core-ktx:2.8.7
+androidx.lifecycle:lifecycle-common:2.9.4
+androidx.lifecycle:lifecycle-livedata-core-ktx:2.9.4
 androidx.lifecycle:lifecycle-livedata-core:2.0.0
-androidx.lifecycle:lifecycle-livedata-core:2.8.7
+androidx.lifecycle:lifecycle-livedata-core:2.9.4
 androidx.lifecycle:lifecycle-livedata:2.0.0
-androidx.lifecycle:lifecycle-livedata:2.8.7
-androidx.lifecycle:lifecycle-process:2.8.7
-androidx.lifecycle:lifecycle-runtime-android:2.8.7
-androidx.lifecycle:lifecycle-runtime-compose-android:2.8.7
-androidx.lifecycle:lifecycle-runtime-compose:2.8.7
-androidx.lifecycle:lifecycle-runtime-ktx-android:2.8.7
-androidx.lifecycle:lifecycle-runtime-ktx:2.8.7
+androidx.lifecycle:lifecycle-livedata:2.9.4
+androidx.lifecycle:lifecycle-process:2.9.4
+androidx.lifecycle:lifecycle-runtime-android:2.9.4
+androidx.lifecycle:lifecycle-runtime-compose-android:2.9.4
+androidx.lifecycle:lifecycle-runtime-compose:2.9.4
+androidx.lifecycle:lifecycle-runtime-ktx-android:2.9.4
+androidx.lifecycle:lifecycle-runtime-ktx:2.9.4
 androidx.lifecycle:lifecycle-runtime:2.1.0
-androidx.lifecycle:lifecycle-runtime:2.8.7
-androidx.lifecycle:lifecycle-viewmodel-android:2.8.7
-androidx.lifecycle:lifecycle-viewmodel-compose-android:2.8.7
-androidx.lifecycle:lifecycle-viewmodel-compose:2.8.7
-androidx.lifecycle:lifecycle-viewmodel-ktx:2.8.7
-androidx.lifecycle:lifecycle-viewmodel-savedstate:2.8.7
+androidx.lifecycle:lifecycle-runtime:2.9.4
+androidx.lifecycle:lifecycle-viewmodel-android:2.9.4
+androidx.lifecycle:lifecycle-viewmodel-compose-android:2.9.4
+androidx.lifecycle:lifecycle-viewmodel-compose:2.9.4
+androidx.lifecycle:lifecycle-viewmodel-ktx:2.9.4
+androidx.lifecycle:lifecycle-viewmodel-savedstate-android:2.9.4
+androidx.lifecycle:lifecycle-viewmodel-savedstate:2.9.4
 androidx.lifecycle:lifecycle-viewmodel:2.1.0
-androidx.lifecycle:lifecycle-viewmodel:2.8.7
+androidx.lifecycle:lifecycle-viewmodel:2.9.4
 androidx.loader:loader:1.0.0
-androidx.localbroadcastmanager:localbroadcastmanager:1.0.0
-androidx.print:print:1.0.0
 androidx.profileinstaller:profileinstaller:1.4.0
 androidx.recyclerview:recyclerview:1.4.0
 androidx.resourceinspection:resourceinspection-annotation:1.0.1
-androidx.savedstate:savedstate-ktx:1.2.1
+androidx.savedstate:savedstate-android:1.3.1
+androidx.savedstate:savedstate-android:1.3.3
+androidx.savedstate:savedstate-compose-android:1.3.3
+androidx.savedstate:savedstate-compose:1.3.3
+androidx.savedstate:savedstate-ktx:1.3.1
+androidx.savedstate:savedstate-ktx:1.3.3
 androidx.savedstate:savedstate:1.0.0
-androidx.savedstate:savedstate:1.2.1
+androidx.savedstate:savedstate:1.3.1
+androidx.savedstate:savedstate:1.3.3
 androidx.startup:startup-runtime:1.1.1
 androidx.tracing:tracing:1.0.0
+androidx.tracing:tracing:1.2.0
 androidx.transition:transition:1.5.0
 androidx.vectordrawable:vectordrawable-animated:1.1.0
 androidx.vectordrawable:vectordrawable:1.1.0
@@ -118,7 +128,7 @@
 com.google.android.gms:play-services-maps:18.0.2
 com.google.android.gms:play-services-tasks:18.2.0
 com.google.android.gms:play-services-wallet:19.4.0
-com.google.android.material:material:1.12.0
+com.google.android.material:material:1.13.0
 com.google.errorprone:error_prone_annotations:2.15.0
 com.google.guava:listenablefuture:1.0
 com.squareup.moshi:moshi-kotlin:1.15.0
@@ -128,21 +138,18 @@
 com.squareup.okio:okio:3.6.0
 com.tencent.mm.opensdk:wechat-sdk-android-without-mta:6.8.0
 org.bouncycastle:bcprov-jdk15to18:1.84
-org.jetbrains.kotlin:kotlin-android-extensions-runtime:1.9.25
 org.jetbrains.kotlin:kotlin-bom:1.8.22
-org.jetbrains.kotlin:kotlin-parcelize-runtime:1.9.25
+org.jetbrains.kotlin:kotlin-parcelize-runtime:2.3.21
 org.jetbrains.kotlin:kotlin-reflect:1.8.22
-org.jetbrains.kotlin:kotlin-stdlib-common:2.0.0
-org.jetbrains.kotlin:kotlin-stdlib-common:2.0.20
+org.jetbrains.kotlin:kotlin-stdlib-common:2.3.21
 org.jetbrains.kotlin:kotlin-stdlib-jdk7:1.9.10
 org.jetbrains.kotlin:kotlin-stdlib-jdk8:1.9.10
-org.jetbrains.kotlin:kotlin-stdlib:2.0.0
-org.jetbrains.kotlin:kotlin-stdlib:2.0.20
-org.jetbrains.kotlinx:kotlinx-coroutines-android:1.9.0
-org.jetbrains.kotlinx:kotlinx-coroutines-bom:1.9.0
-org.jetbrains.kotlinx:kotlinx-coroutines-core-jvm:1.9.0
-org.jetbrains.kotlinx:kotlinx-coroutines-core:1.9.0
-org.jetbrains.kotlinx:kotlinx-coroutines-play-services:1.9.0
+org.jetbrains.kotlin:kotlin-stdlib:2.3.21
+org.jetbrains.kotlinx:kotlinx-coroutines-android:1.11.0
+org.jetbrains.kotlinx:kotlinx-coroutines-bom:1.11.0
+org.jetbrains.kotlinx:kotlinx-coroutines-core-jvm:1.11.0
+org.jetbrains.kotlinx:kotlinx-coroutines-core:1.11.0
+org.jetbrains.kotlinx:kotlinx-coroutines-play-services:1.11.0
 org.jetbrains.kotlinx:kotlinx-datetime-jvm:0.4.1
 org.jetbrains.kotlinx:kotlinx-datetime:0.4.1
 org.jetbrains.kotlinx:kotlinx-serialization-bom:1.7.3
@@ -151,6 +158,7 @@
 org.jetbrains.kotlinx:kotlinx-serialization-json-jvm:1.7.3
 org.jetbrains.kotlinx:kotlinx-serialization-json:1.7.3
 org.jetbrains:annotations:23.0.0
+org.jspecify:jspecify:1.0.0
 project :3ds2
 project :ach
 project :action-core

To check the affected modules run the aggregateDependencyLists gradle task with includeModules=true.

Comment thread .editorconfig
Comment thread .github/workflows/update_verification_metadata.yml
@jreij
jreij force-pushed the renovate/v5-all-v5 branch from 452bdf8 to d2d947f Compare August 14, 2026 11:20
Comment thread .github/workflows/get_dependency_list.yml
Comment thread .github/workflows/release_acceptance_app.yml
remoteUrl = URI(
"https://github.com/Adyen/adyen-android/tree/main/$projectName/src/main/java",
).toURL()
remoteUrl("https://github.com/Adyen/adyen-android/tree/main/$projectName/src/main/java")

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
remoteUrl("https://github.com/Adyen/adyen-android/tree/main/$projectName/src/main/java")
remoteUrl("https://github.com/Adyen/adyen-android/tree/v5/$projectName/src/main/java")

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed


@Test
fun `then loading state should be propagated properly`() {
fun `then loading state should be propagated properly`() = runTest {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why is this needed?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Aligning with this commit 20d7edc

- name: Deploy GitHub Pages
uses: JamesIves/github-pages-deploy-action@v4.7.3
uses: JamesIves/github-pages-deploy-action@d92aa235d04922e8f08b40ce78cc5442fcfbfa2f # v4.8.0
with:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

By using target-folder we could have the docs for both v5 and v6. WDYT?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good idea! We'll need to investigate how the publishing itself will work as well, will we have one path for v5 and another for v6? I think since we're not publishing docs for v6 yet we should do this later, WDYT?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

To explain more, we can have:

Or

And we need to check if this even works out of the box with the current dokka configuration

jreij added 21 commits August 18, 2026 14:40
AGP 9 no longer allows applying kotlin-android, which is what previously put the Kotlin Gradle Plugin on the root buildscript classpath. The versionless `kotlin-parcelize` alias in the version catalog needs KGP there in order to resolve, so without it the parcelize compiler plugin silently generates nothing and every @parcelize class fails to compile with "is not abstract and does not implement abstract members: describeContents / writeToParcel".

Adding `alias libs.plugins.kotlin.compose apply false` to the root build restores KGP on the classpath, matching how main does it. Compose is incidental here — `apply false` only resolves the plugin onto the buildscript classpath and applies it to nothing, so no module gains the Compose compiler and no published artifact changes. Do not remove this line.

Also drops the now-obsolete `compose-compiler` entry and the `kotlin-android` / `jetbrains-kotlin-android` aliases, which AGP 9's built-in Kotlin support makes redundant.
Completes the Dokka V2 migration that build-logic already assumed: adds the `pluginMode=V2Enabled` opt-in flags and replaces the V1 `dokkaHtmlMultiModule` aggregation in the root build with main's `dokka(project(...))` form, using v5's module list.

`publish_docs.yml` also deployed `build/docs/`, which is where the removed V1 block wrote its output. Dokka V2 writes to `build/dokka/html/`, so the workflow was publishing nothing on a clean checkout. The same bug exists on main and needs porting there — it went unnoticed because that workflow last ran before the V2 migration landed.
Ports main's CI Gradle configuration from #2429. A `.github/ci-gradle.properties` is copied over `~/.gradle/gradle.properties` before each Gradle run, which takes precedence over the project file, so CI can be tuned without changing what developers get locally. Its only difference from the committed `gradle.properties` today is a 4g max heap instead of 3072m, but on main it has since been the place where the daemon and heap were tuned for CI.

Also adds `cache-encryption-key` to every `setup-gradle` step that lacked it. Without it the Gradle configuration cache is neither stored nor restored between runs, so v5 was getting almost none of the caching that change was meant to deliver: only 2 of 13 Gradle workflows had the key.
Ports 1cd53b7 from main. The Azul Zulu API (api.azul.com) intermittently returns 520 errors, causing setup-java to fail. Temurin (Eclipse Adoptium) downloads from GitHub-hosted releases and does not depend on external APIs.
Ports 283127a and fd70334 from main. By using standard libraries it is not needed to use 3rd party libraries. This mitigates several security risks:
- Python dependencies should be locked to verified versions
- Python package manager scripts should not be executed during installation

The four CI scripts move from `toml` to `tomllib` and from `requests` to `urllib.request`, so the four `pip install` calls in the workflows can go, and `setup-python` pins the interpreter where a recent enough stdlib is needed. This matters most in the publishing pipeline, which ran an unpinned `pip install` on a runner holding Sonatype credentials.

`validate_dependencies_for_release_notes.py` keeps computing its merge base against `origin/v5`, which is the only intended difference from main's copy.
Ports f21fb50 from main. `ad-m/github-push-action` was pinned to the mutable `master` ref while holding repo write access, to do something git does natively in one line.

Also drops two stale comments claiming Java 17 where the workflow uses 21, and which the CI gradle.properties step had left attached to the wrong step.
Ports b62abfc and 7ffc572 from main. This should remove the overhead of starting new jobs: starting a runner, checking out the project, setting up the environment, etc.

It also removes a full duplicate build on every PR. `sonar_cloud.yml` re-ran `detekt assDeb koverXmlReport lintDeb`, the same tasks the other five jobs had just finished, and did so on a 2-core runner rather than the 8-core one the rest of the build uses. Sonar now runs in the same job and reuses its outputs.

Six jobs become one: detekt, ktlint, assemble, test, lint and sonar were spread across `assemble.yml`, `run_tests.yml`, `code_analysis.yml` and `sonar_cloud.yml`, which are all removed.

Two smaller consequences of matching main. The SonarCloud package cache step is gone, as it was on main when `sonar_cloud.yml` was deleted there; Gradle's own cache still applies. The `chmod +x gradlew` steps are gone too, since `gradlew` is already mode 100755 in git.

Secrets are still passed with `inherit`. Switching to explicit per-secret passing is left to its own commit so it can be reviewed as one change.
Ports the add_pr_label part of c900c7e (main's "Sonar security house keeping"). `${{ }}` expressions are substituted into the script before the shell sees them, so interpolating `pull_request.head.ref` directly into a `run` block lets a crafted branch name execute commands on the runner. Passing it through `env` makes the shell treat it as data.

Also scopes permissions per job rather than granting `pull-requests: write` to the whole workflow, so the job running the script only has `contents: read`. That is what made the injection worth fixing rather than merely noting: the vulnerable job held the write token.
Ports the permission scoping from main. Five workflows granted their widest permission at the workflow level, so every job inherited it: `check_pr` gave `contents: write` and `pull-requests: write` to all four jobs, and the release workflows gave `contents: write` to jobs that only read.

Each job now declares what it needs. The resulting permissions are identical to main's, job for job, with the exception of main's `version_info` job in `finalize_release`, which is part of its prerelease handling and does not exist on v5.

This matters most where a job runs code it does not control: before this, the job in `check_pr` that builds and tests a contributor's branch held write access to the repository and its pull requests.
v5 is a maintenance branch and no longer runs instrumentation tests on push. The workflow was standalone, so nothing else referenced it.
…rkflow

The job had no permissions declaration at all, so it ran with the repository default while building and signing an app. It now declares `contents: read`, matching main.

Also switches to the `inputs` context, which resolves for `workflow_dispatch` as well as `workflow_call`, and takes main's comment recording which release the pinned Firebase action SHA corresponds to.

The `workflow_call` block main has on this workflow is not ported: it exists so `release_nightly_app.yml` can call it, and v5 has no nightly builds.
Places `permissions:` after `runs-on:` and `needs:` as main does, rather than before them. The parsed workflows are unchanged; this only removes diff noise between the branches that the previous commit introduced.
Ports main's version of the check and its `process_api_changes.sh`. The previous approach ran `apiCheck`, redirected Gradle's stderr to a file and decided pass or fail on whether that file was empty, which had two problems.

A new module's `.api` file is untracked, so it could pass unnoticed. Running `apiDump` and marking the results intent-to-add means new files appear in `git diff` and are reported like any other change.

The PR comment step also failed on pull requests from forks, where the token cannot write a comment. It is now guarded to run only for same-repository pull requests.

Detection is a `git diff` over `**/*.api` rather than a scrape of Gradle's stderr, and the report script parses that diff instead of pairing up files found on disk. Verified against the API dump commit on this branch: 45 modules reported for 45 changed `.api` files, and an empty diff reports no changes.
Ports c900c7e and 6b32dda from main, which fixed a Sonar security hotspot. `secrets: inherit` hands every repository secret to a nested workflow regardless of what it needs, so the publishing workflow received the Gradle encryption key and the build received the Sonatype credentials and signing keys.

Each reusable workflow now declares the secrets it uses and each caller passes exactly those. `GITHUB_TOKEN` is a reserved name that cannot be declared under `on.workflow_call.secrets`, so it is passed as `github-token`, matching main.

Also drops the Gradle encryption key from `get_dependency_list`, which main does not give one. It was added here earlier in this branch, but the secret would have had to be threaded through `check_dependency_changes` to reach it, and main accepts the loss of configuration-cache reuse for that job.

Verified by cross-checking every call site against every declaration: no `inherit` remains, every required secret is passed, nothing undeclared is passed, and no workflow references a secret it has not declared.
Drops four comments in `publish_docs.yml` that main no longer carries, one of which claimed Java 17 where the workflow uses 21, and restores the blank line around the secrets block in `publish_to_maven_central.yml` that the previous commit disturbed.

`publish_to_maven_central.yml` is now identical to main, and `publish_docs.yml` differs only by the Dokka output directory, which is a fix main still needs.
The workflow is triggered only by `schedule`, and GitHub runs scheduled workflows from the default branch alone, so this copy on v5 has never run and never will. Issues belong to the repository rather than to a branch, and main's copy already manages them.
[skip update-verification-metadata]
@jreij
jreij force-pushed the renovate/v5-all-v5 branch from 210e519 to 1cadf91 Compare August 18, 2026 12:41
@github-actions

Copy link
Copy Markdown
Contributor

✅ No public API changes

@sonarqubecloud

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
10.0% Coverage on New Code (required ≥ 80%)

See analysis details on SonarQube Cloud

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Dependencies [PRs only] Indicates a dependency update

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants